Showing posts with label IT CONTROLS. Show all posts
Showing posts with label IT CONTROLS. Show all posts

Tuesday, February 1, 2022

IT Management Controls Book

 

IT Management Controls Book

 

 

I am glad to announce the publication of my new IT book, as noted next:

 

IT Management Controls

Governing IT Operations and Systems more effectively

Author: John Kyriazoglou

Language: English

Edition: 1st

Public Link: https://bookboon.com/en/it-management-controls-ebook

Premium, After Login: https://bookboon.com/premium/books/it-management-controls

Overview

 

This book includes over five hundred (about 502) IT management controls (policies, procedures, practices, forms, etc.) organized in 10 chapters and 23 appendices.

 

These are related to all aspects of governing IT, such as:  organizing the IT function, managing IT operations and activities, developing and running Application Systems, ensuring adequate security of computerized facilities, systems and networks, etc.

 

The types of IT Management Controls include examples of: an IT Ethics Code, IT Standards, IT Function and IT Job Descriptions, IT Policies, IT Procedures, IT Documentation, IT Manuals, IT Reports, IT Agreements, IT Statements, IT Methodologies, IT Forms, IT Plans, IT Practices, IT Detail Controls, Hardware and Software Tools, etc.

 

 

Please feel free to share this announcement with your contacts.

 

Thank you for your time and attention.

 

Best regards,

 

John Kyriazoglou

 

 

Friday, December 14, 2012

OECD IT Security Guidelines


OECD IT Security Guidelines

John Kyriazoglou*
Establishing the IT security guidelines and standards (in general terms) for the specific organization should be done by the IT committee and ratified by the board. These standards could follow international guidelines and frameworks issued by organizations such as OECD, NIST (U.S.A.),  European Union, IATF, ISO (ISO/IEC 17799, ISO/IEC 27001, ISO 13335, ISO 15408), U.S. Federal Information Processing Standard (FIPS 140), etc.

I have used the following security principles of OECD in my IT security projects and particularly when large public or private organizations are involved.

PRINCIPLE 1: Awareness. Participants should be aware of the need for security of information systems and networks and what they can do to enhance security.

PRINCIPLE 2: Responsibility. All participants are responsible for the security of information systems and networks.

PRINCIPLE 3: Response. Participants should act in a timely and co‑operative manner to prevent, detect and respond to security incidents.

PRINCIPLE 4: Ethics. Participants should respect the legitimate interests of others.

PRINCIPLE 5: Democracy. The security of information systems and networks should be compatible with essential values of a democratic society.

PRINCIPLE 6: Risk assessment. Participants should conduct risk assessments.

PRINCIPLE 7: Security design and implementation. Participants should incorporate security as an essential element of information systems and networks.

PRINCIPLE 8: Security management. Participants should adopt a comprehensive approach to security management.

PRINCIPLE 9: Reassessment. Participants should review and reassess the security of information systems and networks, and make appropriate modifications to security policies, practices, measures and procedures.

 


John Kyriazoglou (jkyriazoglou@hotmail.com)

John Kyriazoglou, CICA, B.A (Hon-University of Toronto)

International IT and Management Consultant, author of several books



SSRN Free Publications: http://ssrn.com/author=1315434

 

 

Wednesday, November 28, 2012

Free IT-Business Alignment Book


Free IT-Business Alignment Book


Please check out the following two links. They contain my latest free e-book on how to align your IT systems to your business operations better.


http://bookboon.com/en/business-ebooks/it/it-business-alignment-part-i


http://bookboon.com/en/business-ebooks/it/it-business-alignment-part-ii


Regards,


John Kyriazoglou


 

Free IT-Business Alignment Book


Free IT-Business Alignment Book


Please check out the following two links. They contain my latest free e-book on how to align your IT systems to your business operations better.


http://bookboon.com/en/business-ebooks/it/it-business-alignment-part-i


http://bookboon.com/en/business-ebooks/it/it-business-alignment-part-ii


Regards,


John Kyriazoglou


 

Wednesday, November 14, 2012

IT CONTROLS EVALUATION AUDIT PROGRAM

Topic: IT Controls Audit Program
Message:

IT CONTROLS EVALUATION AUDIT PROGRAM

Here is an audit program you may use if you want to manage and improve your IT operations.

The objective of the checklists contained in this audit program is to support, enable and facilitate IT managers in establishing better the IT function and its components and auditors in evaluating the organizational, security and performance aspects of the IT function of the organization.

T Terms of Reference Checklist

1. Is the CIO/IT Manager reporting to the official / organizational responsibility centre of the IT unit?
2. Are the Terms of Reference detailed enough and tailored to the specific activities of each IT function/department and responsibility centre?
3. Are the Board members and/or executive management of the Company/Organization familiar with these terms of reference and have they been ratified at the appropriate executive / board level?
4. Are the IT department managers familiar with these terms of reference?
5. Are the IT department personnel familiar with these terms of reference?
6. Are the IT user managers familiar with these terms of reference?
7. Are the IT users familiar with these terms of reference?
8. Are these terms of reference aiding the IT managers and staff in discharging their duties?
9. Are these terms of reference known to the external stakeholders of IT (maintenance vendors, society interest groups, community groups, regulatory agencies, etc.)?
10. Is the IT function structured effectively to serve the Organization and its divisions / functions: as a separate division, or as a part of another division, or interfacing with an outsource entity, or shared service among several departments, or a combination of above, or a separate company with its own Board of Directors, and at the right organizational and responsibility level?



IT Performance Assessment Checklist

1. IT Performance Policy: Obtain a copy of the IT performance policy and review with IT management.
2. Assess validity of this policy and usage and up to what level (criteria, user satisfaction etc. ).
3. Operational Statistics: Obtain machine statistics for systems running in the data centre
4. Performance Reporting: Assess how IT management records operational statistics on equipment and systems availability and down -time and how these processing problems (and their resolution) are communicated to end-user and Top Management.
5. Carry out, if possible, a comparison cost analysis of this IT Dept. with other IT units of the Group.
6. Hardware Capacity Planning: Assess computer performance and capacity planning process, especially for computer hardware upgrades.
7. Review the IT Governance Framework.
Consider the following issues: The IT Governance framework should be established and communicated to all. Examine if the IT Governance framework is aligned with a standard model such as COBIT/ISACA, or the ITIL model.
8. Review Key Performance Indicators and their effectiveness for the particular IT function audited.
Consider the following IT performance measures:
Development / maintenance activity (Functions developed worth to users, No. of lines coded / tested / changed, Hours spent on maintenance (person, program)
Operational performance (Timely delivery of reports to users, Average response time, Average availability time, Volume of data stored, Mean time between failures, No. of lines printed, Volume of data maintained, No. of on-line transactions processed)
Financial performance (Adherence to budget, Expenditures on maintenance vs. new development, Expenditures on preventative maintenance, Ratio of administrative (staff)) costs to production (line) costs
Human resource management (Turn over ratios, Training per employee (amounts, hours), Average tenure within the company).


IT Security Assessment Checklist

Basic Management Issues

1. Determine who has responsibility for IT Security for the organization and assess whether it is the right level of management.
2. Ensure that procedures for the preparation, approval, and monitoring of IT strategic plans are implemented and these plans are in alignment with the strategic plan of the organization.
3. Examine the organizational security policy and compare it to the IT security policy to ensure that both of these serve the same purpose and needs.
4. Ensure that the IT security policy contains at least data classification and security penetration testing for all critical IT systems and services.
5. Assess the IT management reporting method to ensure that all IT issues are reported and monitored.
6. Assess the operation of the IT review mechanisms between end-users and IT, such as: Ι.Τ. Steering Committee, User Liaison Group, και Project Steering Committee, etc.
7. Review the resolution procedures for security problems and ensure that these resolve all reported security incidents satisfactorily.
8. Ensure that all security issues are made known via written reports and discussions to higher levels of management, including the board members.
9. Ensure that the evaluation of information security status is executed on the basis of: self-assessments, onsite audit reviews, penetration testing, onsite technical evaluations, ethics assessments, data quality testing, and best practice benchmarking.

Human Resource Management

1. Review the organizational charts and job descriptions to ensure that there is adequate segregation of duties in terms of security issues.
2. Review the training and education programs and budget to ensure that all personnel have been given the approved training on security related matters.
3. Assess the effectiveness of support provided by IT and other security mechanisms to the end-users on IT security issues.

IT Procurement Procedure

1. Review the IT procurement policy and procedures to ensure that all IT purchases are examined from the security perspective.
2. Review a good sample of IT purchase documentation to ensure that the formal IT policy and procedures are been implemented properly.
3. Review the major IT hardware and software contracts to ensure that the formal IT policy and procedures are been implemented properly.
4. Review the Computer Insurance policy of the organization to ensure that major risks of IT hardware and software systems are covered adequately.

Contingency Planning

1. Review the IT contingency plan and ensure that all critical IT systems are covered.
2. Ensure that this plan is reviewed and tested on a periodic basis.
3. Review the backup policy and procedures to ensure that these are adequately implemented and monitored by IT management.
4. Review the backup register to ensure that this is kept up to date.
5. Review both the onsite and offsite vault procedures.
I.T. Legislation Compliance
1. Determine which national and international laws and regulations pertaining to IT issues are relevant to the organization.
2. Ensure that proper licenses exist for all IT software and hardware purchased.
3. Test compliance with IT legislation, including data privacy and copyright issues.

Physical and Environmental Controls

1. Ensure that physical access controls are enforced in accordance with the corporate security policy and professional practices for the following: Wholly owned buildings, Shared buildings, Central computer room and server rooms, Personal computers and work stations, Peripheral equipment, such as: modems, routers, printers, etc., Magnetic and other digital media, and Technical manuals and documentation.
2. Ensure that management controls are enforced to protect buildings, personnel, equipment and media in accordance with the corporate security policy, vendor guidelines, and professional health and safety practices against the following: Fire, Flood, Power fluctuations, Static electricity, Storms, and Food and beverage accidents, etc..

System Development and Maintenance

1. Assess the system development and maintenance procedures to ensure that they are adequate in terms of security in all phases, such as: Analysis, design, construction, testing, implementation, and support.
2. Review the system development and maintenance procedures to ensure that all phases are signed off by the key end-users.
3. Review the programming standards to ensure that they handle the security issues related to interfacing with other operating system software and application systems.
4. Review the program library maintenance procedures to ensure that all programs are fully tested and their movement to production status approved before they are transferred to the production library.

Data Center Operations

1. Assess the adequacy of controls to ensure that the correct production files are used in all application systems running in the data center.
2. Review all logs to ensure that all events are recorded and monitored.
3. Assess the adequacy of backup and recovery procedures.
4. Assess the adequacy of external party maintenance and support procedures.

Software and data security

1. Ensure that general procedures and specific measures are implemented to protect against illegal access to the system, its utilities, the program libraries, the system and application software, the data files, etc.
2. Assess the adequacy of the general procedures and specific measures implemented to protect against illegal access to the system, its utilities, the program libraries, the application software, the data files, etc.
3. Ensure that passwords are used for each set of users and corresponding applications and for each class of actions (update, delete, read, remote access, etc.) and that these passwords are changed according to the corporate password policy.
4. Ensure that users cannot run their own programs to access production libraries and production data.
5. Ensure that IT personnel cannot access production data without specific authorization.

For more on IT controls, see my books:
IT Strategic & Operastional Controls,
available at Amazon and IT Governance

Regards,

Friday, November 4, 2011

IT CONTROLS BOOK-FREE MATERIAL

PLEASE SEE MY TWO IT CONTROLS BOOKS  

BOOK (1): 'IT STRATEGIC AND OPERATIONAL CONTROLS’

Author: John Kyriazoglou, Publisher: IT Governance Publishing

ISBN: 978-1-84928-061-7, Pages: 686, Format: Softcover, Date: 2 September 2010

Available at:

PRINTED VERSION:                    www.itgovernance.co.uk/products/3066

E-BOOK FORMAT VERSION:    www.itgovernance.co.uk/products/3067

These can also be purchased from other major world distributors (e.g. AMAZON), etc.) and bookstores in several countries (England, India, Switzerland, Canada, Australia, Japan, etc.).

 For a FULL LIST of CONTENTS  and a SAMPLE of what is contained in this book, please see: http://www.linkedin.com/pub/john-kyriazoglou/0/9b/919

And follow to ‘Published Books/IT_CONTROLS_BOOK_Contents_Sample.PDF’.


 Book Testimonial

'John Kyriazoglou has produced a book that is very thorough, useful and a good source of information on a complex subject area ... John Kyriazoglou has a wealth of experience in this area and he has shared this well with the wider community. His book is a welcome addition to the field.'

Rob Ratcliff, UKSMA Chair (2011)

BOOK (2): ‘ ADDENDUM to IT STRATEGIC AND OPERATIONAL CONTROLS’

ISBN 978-1-84928-075-4. www.itgovernance.co.uk/products/3143

This separate volume contains Customisable IT audit programmes and checklists in word format.

 For a FULL LIST of CONTENTS  and a SAMPLE of what is contained in this book, please see: http://www.linkedin.com/pub/john-kyriazoglou/0/9b/919

And follow to ‘Published Books/IT_CONTROLS_BOOK_Contents_Sample.PDF’.



PDF: ‘ IT_CONTROLS_EXAM_MCQs

 This document contains 100 Multiple Choice Questions (and Answers) which are based on the book by John Kyriazoglou (‘IT STRATEGIC AND OPERATIONAL CONTROLS’, as described above) and is available, free of charge, as described next.


And follow to ‘Published Books/IT_CONTROLS_EXAM_MCQs.PDF’.



Saturday, October 8, 2011

BENEFITS OF IT CONTROLS


BENEFITS OF IT CONTROLS





John Kyriazoglou*, CICA, M.S, B.A(Honours), IT Consultant and Author (jkyriazoglou@hotmail.com)

                       



“It is possible to fail in many ways, while to succeed is possible only in one way”

                                                                        Aristotle (384 B.C. – 322 B.C.)





“Computers are useless. They only give you answers”

                                                            Pablo Picasso (1881 – 1973)



“The global information society is increasingly dependent on electronic networking and exchanging ‘electronic goods’ with high economic value, both in private life and in business.”

                        Prof. Heinz Thielmann, Fraunhofer Institute, Germany (2006)



The most critical assets, in the 21st century, for the private and public enterprises, for organizations in general, for the global society, and for the economy (local, national, international) are not of physical nature (equipment, machines, installations, plants), or of financial nature (money, credit or other financing instruments), or of computer software nature.



The most critical assets are the knowledge and ideas (concepts) that exist in the brains of people, which are stored in computerized systems (personal and corporate), in the modern business environment.



The computer technology and related infrastructure, the information systems, the network backbone (intranet, extranet, metropolitan, Internet, etc.) and related media technologies give everyone, within a given organizational environment, direct access to what is going on: within the given organization, in the industrial sector to which it belongs, and in the general economy and market in which it operates.



All these technological components, broadly termed Information Technology (IT) and the related Information Systems (IS) which operate within its realm enable the modern private and public corporation and/or organization to accrue the following benefits (indicative only):



(1) Quicker and more effective information for decision-making at all levels,

(2) Increased competition in all services of the firm,

(3) Improved production processes and procedures, and

(4) Higher quality in products and services offered by information systems to customers (and citizens) and society in general.



Given the rate of development of the information processing and computer manufacturing technologies and processes, a rate without a precedent in the history of man-kind, it is possible now for organizations to transfer almost all of their daily business operations to be carried out by integrated information systems.



These systems are like medical drugs, either strengthening the organization, or enabling it to cure or resolve a particular problem or operating malfunction.

But, using the drug analogy, if these systems are not used in a disciplined manner, they can create havoc and many times bring about not the expected results and even catastrophe.



These integrated information systems must therefore operate within a business environment which is ruled by the rules, policies, regulations and instructions of a corporate governance framework and a related information technology governance framework.



As Negroponte has said (see Nicholas Negroponte: “Being Digital”, Alfred A. Knopf, N. York, U.S.A., 1995): “The next decade will see cases intellectual property abuse and invasion of our privacy. We will experience digital vandalism, software piracy and data thievery”.



This has definitely been proven correct. Security incidents and other acts of electronic and computer-based crimes are on the rise (as per www.cert.org and other security-related sites).



And as the notorious Mitnick has said (see book by Kevin. D. Mitnick and William L. Simor: “The art of deception”, Wiley, 2002): “Valuable information must be protected no matter what forum it takes or where it is located. An organization’s customer list has the same value whether in hard-copy form or an electronic file at your office or in a storage box. Social engineers always prefer the easiest to circumvent, least defended point of attack. A company’s offsite backup storage facility is seen as having less risk of detection or getting caught. Every organization that stores any valuable, sensitive, or critical data with third parties should encrypt their data to protect its confidentiality”.



Also IT auditing will enhance the qualities of information (effectiveness, efficiency, confidentiality, integrity, availability, compliance, reliability) according to ISACA (www.isaca.org).



The answer for managers and leaders of organizations is to plan for this new operating environment with the proper tools, methodologies and resources.



Never forget that because organizations differ, their control needs also will differ. For example, all groups need change management, but how it's implemented will depend on the enterprise. Delving into the work instruction level, access controls are needed, but how they are handled on a mainframe vs. a Windows network will vary. The point is that you will need to tune your policies, procedures and work instructions not only to meet the spirit of the controls but also to be feasible in the context of your organization.



In almost all types of organizations, both private and public, corporate controls denote the set of policies, procedures, techniques, methods, and practices to manage and control their business operations.



Within this corporate controls governance framework Information Technology controls (or IT controls) are specific actions, usually specified by policies, procedures, practices, etc., performed by persons, hardware or software with the main objective to ensure that specific business objectives are met.



The overall guiding aim of IT controls relate to the secure processing, confidentiality, integrity, and availability of data and the overall management of the IT function of the organizations.



IT controls are commonly described in two categories according to various sources (www.isaca.org", www.isaca.org, www.theiia.org, www.theiia.org, www.itpi.org): IT General Controls and IT Application Controls.



IT General Controls are those controls that are applicable to all IT activities (systems, services, issues, processes, operations, etc.) and data for a given organization or IT systems environment. They include controls over such areas as the strategy for IT, systems development, data center operations, data base and data communications infrastructure, systems software support and maintenance, IT security, and ready-made application systems acquisition, development and maintenance.



IT Application controls are those controls that are appropriate for transaction processing by individual computerized subsystems, such as financial accounting, personnel administration, customer sales, inventory control, payroll or accounts payable, etc.



They relate to the processing and storing of data in computer-based files by individual IT applications and help ensure that business transactions occurred, are authorized, and are completely and accurately recorded, stored, processed, and reported. 

Benefits of the existence of IT Controls to business include:



(1) Understand and control the associated risks of IT systems.



(2) Improve the process of designing, implementing and auditing new and existing IT systems.



(3) Increase management’s aptitude to achieve operational goals. With well-controlled, integrated and robust IT systems, you can gain a comparative advantage in a

competitive environment, whilst ensuring that information is relevant, accurate and timely.

(3) Ensure high standards within your IT systems.



---------------------------------------------------------------------------------------------------------------

* For more information on IT Controls, see the book:



'IT STRATEGIC AND OPERATIONAL CONTROLS'



PRINTED VERSION:                www.itgovernance.co.uk/products/3066

E-BOOK FORMAT VERSION:    www.itgovernance.co.uk/products/3067

CUSTOMISABLE IT AUDIT PROGRAMMES AND CHECKLISTS (WORD FORMAT): www.itgovernance.co.uk/products/3143



Author: John Kyriazoglou

Publisher: IT Governance Publishing

ISBN: 9781849280617

Pages: 686

Format: Softcover

Published date: 2 September 2010